← PRODUCTS / MEDIA PLATFORM
P-05○ Beta

VOD DRM Platform

Self-hosted VOD DRM platform

A microservices-based, self-hosted VOD DRM platform spanning FFmpeg HLS encoding, SPEKE v2.0 DRM keys and licensing (Widevine · PlayReady · FairPlay), R2 storage, and a DRM player.

Self-hosted
drm@platform — boot.log
$ docker-compose up -d
✓ drm-gateway :9705
✓ drm-encoding :9704
✓ drm-key (SPEKE) :9706
✓ drm-license :9707
✓ drm-player :9710
→ 11 services healthy
▶ ready to stream
UploadEncodeKeyPkgStorageStreamLicensePlay
/02PROBLEM

The problems VOD DRM Platform
solves

This product was built to solve the recurring operational and development challenges found in real environments like the ones below.

CONTEXT

A microservices-based, self-hosted VOD DRM platform spanning FFmpeg HLS encoding, SPEKE v2.0 DRM keys and licensing (Widevine · PlayReady · FairPlay), R2 storage, and a DRM player. Existing solutions were either not operator-friendly or built in a way that piled up maintenance costs. UNISYS redesigned this into a product that's owned all the way through operations.

/03FEATURES

Key Features

The core features VOD DRM Platform provides. Every feature is delivered in an operable form.

F-01

Admin dashboard

Manage content, users, and encoding jobs, monitoring everything from content upload to encoding job creation and status in one console.

F-02

HLS encoding pipeline

Transcode sources into multi-quality HLS (1080p · 720p · 480p · 360p) with FFmpeg, tracking job progress in real time.

F-03

DRM keys · Licensing (SPEKE v2.0)

Generate content keys and PSSH per the SPEKE v2.0 standard, and issue/validate Widevine, PlayReady, and FairPlay licenses.

F-04

DRM-protected player

A web player (FastAPI and Flask builds) that acquires a license after JWT authentication and plays encrypted HLS.

F-05

Notifications · Webhooks

Deliver key events such as encoding completion via email, Slack, Discord, and webhooks.

F-06

R2 storage · Microservices

Transfers encoding output to Cloudflare R2 (S3-compatible), with 8+ microservices that scale and deploy independently.

/04ARCHITECTURE

Technical Architecture

An overview of the technologies VOD DRM Platform runs on.

C-01
Runtime
Python 3.13 · Docker · Docker Compose (multi-arch amd64/arm64)
C-02
Backend
FastAPI · Flask · SQLAlchemy · Uvicorn/Gunicorn · JWT
C-03
Database / Storage
MySQL 8.0 · Redis · Cloudflare R2 (boto3)
C-04
DRM / Media
SPEKE v2.0 · Widevine · PlayReady · FairPlay · FFmpeg · Shaka Packager
/05FAQ

Frequently Asked Questions

The questions we hear most often when evaluating adoption.

A basic setup (dashboard, encoding, key, license, player) typically takes 3–4 business weeks; 6–8 weeks when migrating existing content or building custom integrations.
Yes. All components ship as Docker Compose multi-arch (amd64/arm64) images to run on your own infrastructure.
Each service exposes a REST API with auto-generated docs (Swagger /docs) and notification webhooks (email · Slack · Discord), and DRM key issuance follows the SPEKE v2.0 standard.
Widevine, PlayReady, and FairPlay, with a SPEKE v2.0 key server and license server issuing and validating encrypted HLS.
START A PROJECT

Ready to start your project?

If you're planning a software product, SaaS, or cloud infrastructure build,
let's discuss your project with UNISYS.

Start a Project View Products